This page reflects our reading of Cyber Resilience Act, Article 14 and ENISA SRP guidance as of . It is not legal advice. Review process.
This log records changes to the regulation and the reporting platform Declara tracks — not changes to Declara itself. It's what lets you tell "the law changed" apart from "the product changed." Product release notes live separately.
Convention
One entry per regulatory change, dated YYYY-MM-DD, with a link to its primary
source. Entries are added, never edited in place — if a source is later corrected,
a new entry records that.
Entries
2026-09-11 — CRA Article 14 reporting obligations take effect
The Cyber Resilience Act's Article 14 reporting duties — early warning, notification, and final report for actively exploited vulnerabilities and severe incidents — became applicable on this date, ahead of the Act's general application date.
Source: Cyber Resilience Act, Article 14, checked 2026-09-13.
2026-09-11 — ENISA CRA Single Reporting Platform goes live, web-form only, no API
The SRP launched as the single point of filing to a CSIRT and ENISA simultaneously. It is a web form; there is no API to submit through as of this writing, which is why Declara's report packets are copied into the SRP manually rather than submitted automatically.
Source: ENISA CRA Single Reporting Platform FAQ, checked 2026-09-13.